Information Assurance Engineer
Listed on 2026-02-14
-
IT/Tech
Cybersecurity, Systems Engineer
Simple sense builds, deploys, and sustains the Installation Resilience Platform that enables mission operators to rapidly adapt and respond. The Platform protects critical infrastructure from cyber attack while unlocking previously siloed information to monitor, diagnose, and improve response times to incidents. Our adversaries rapidly adopt the latest technology: we help defense users respond in kind.
Simple sense is a non-traditional defense contractor and prime on the Air Force's Installation Resilience Operations Command and Control (IROC) program, which is now expanding to five additional Air Force, Space Force, and Army installations from the one prototype installation, Tyndall Air Force Base.
Our team combines over 100 years of direct mission experience solving hard problems with 50 years technical expertise deploying Dev Sec Ops , cybersecurity, and cloud infrastructure, giving us a deep appreciation for our customers’ mission and end users’ priorities. We build for scale, architecting and prioritizing technical work for long term sustainability.
Simple sense is looking for a Information Assurance Engineer to join our remote, US-based team. The Information Assurance Engineer will support and execute the all aspects Risk Management Framework (RMF) process. This position will support Simple sense’s end to end RMF implementation, planning, executing, and maintaining all activities required to obtain and sustain system authorizations under the DoD process.
The ideal candidate is an excellent communicator, attentive, and efficient. They can complete work skillfully and independently.
Work Model:
We prioritize candidates in the Denver, CO, San Antonio, TX, and Brooklyn, NY area, but are open to remote talent.
- Locals: 2 days/week onsite.
- Remote:
Quarterly travel for team meetings.
- Support the full RMF A&A lifecycle to achieve and maintain the system Authority to Operate (ATO) with DOD.
- Develop, author, and maintain all core A&A documentation (e.g., SSP, system diagrams, Con Mon plans) within the system’s eMASS record, ensuring all controls, artifacts, and package details are accurate.
- Coordinate with key stakeholders, including Information System Owners, ISSMs, external assessors, and the Authorizing Official Designated Representative (AODR), providing strategic guidance and responding to data requests to ensure the success of all Authorization to Operate (ATO) processes.
- Conduct security assessments, including vulnerability scans, DISA STIG validation, and security control testing. Work with engineering and support teams to facilitate the remediation of identified vulnerabilities and Plans of Action and Milestones (POAMs). In all phases of the RMF process, work to eliminate manual processes with automation.
- Perform continuous monitoring and incident response by leveraging SIEM tools (e.g., Splunk) for log analysis and dashboard creation, conducting vulnerability scans, proactively investigating potential threats, and updating all compliance documentation.
- Administer and maintain enterprise security tools and platforms (e.g., SIEM, EDR, vulnerability scanners), ensuring operational integrity, scalability, and alignment with organizational security policies.
- Provide technical and procedural guidance to engineering and operations staff to ensure secure system design, operation and automation tooling.
- Prepare for and support government cybersecurity audits by staying current on all evolving DoD policies, including DFARS, CMMC, and NIST guidance.
- Executed end-to-end incident response (IR) for cyber events, from initial detection and containment to eradication and recovery.
- Based in Denver, CO, San Antonio, TX, and Brooklyn, NY area - Preferred
- 7+ years of experience with DoD RMF processes
- Prior experience as an ISSM/ISSO
- Deep understanding of NIST SP 800-53 and cybersecurity control implementation
- Experience managing eMASS entries and ATO packages
- Strong technical writing and documentation skills
- Strong understanding of the DoD Zero Trust Strategy, with the ability to operationalize the pillars of Identity, Devices, Networks, Applications, and Data
- Must be a U.S. Citizen and able to obtain a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).